Multiple security vulnerabilities affecting Ivanti Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1.
Unauthenticated Deserialization (CVE-2026-12744, CVE-2026-12745)
Two critical flaws – both CWE-502 Deserialization of Untrusted Data, CVSS 9.8 – let a remote attacker with no credentials at all execute arbitrary code on the server. The attacker simply sends a malicious serialized payload over the network. No login, no privileges, and no user interaction are required.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Ivanti Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1.
Unauthenticated Deserialization (CVE-2026-12744, CVE-2026-12745)
Two critical flaws – both CWE-502 Deserialization of Untrusted Data, CVSS 9.8 – let a remote attacker with no credentials at all execute arbitrary code on the server. The attacker simply sends a malicious serialized payload over the network. No login, no privileges, and no user interaction are required.[emaillocker id="1283"]
Authenticated RCE Flaws (CVE-2026-12650, CVE-2026-12648, CVE-2026-12651)
Three additional deserialization bugs affect authenticated attackers. CVE-2026-12650 scores 9.9 (Critical) because its scope is changed – a compromise can spill beyond the vulnerable component. CVE-2026-12648 and CVE-2026-12651 both score 8.8 (High). All three require only low-level privileges.
Missing Authorization Flaws (CVE-2026-12645, CVE-2026-12646, CVE-2026-12647)
Three CWE-862 Missing Authorization vulnerabilities each score 9.9 (Critical). A low-privileged authenticated user can trigger protected server-side functionality without proper checks. This again results in arbitrary code execution on the server.
Ivanti has confirmed no exploitation in the wild at the time of disclosure.
We recommend you to update Ivanti Neurons for ITSM to version 2026.2.
The following reports contain further technical details:
[/emaillocker]